diff options
author | Micah <micah@riseup.net> | 2015-10-09 19:02:41 +0000 |
---|---|---|
committer | Micah <micah@riseup.net> | 2015-10-09 19:02:41 +0000 |
commit | b3e81589eec604768e08ed56ce5ca42a4b33db89 (patch) | |
tree | 6d05e753d1091049a2dbfb0cb3dddfbc9c99a021 /manifests | |
parent | 571373e0817a6441fb53303736a4666f2a672f26 (diff) | |
parent | 6ea0beb114cdb836cfe9b3ef67504f3641c518ca (diff) | |
download | puppet-sshd-b3e81589eec604768e08ed56ce5ca42a4b33db89.tar.gz puppet-sshd-b3e81589eec604768e08ed56ce5ca42a4b33db89.tar.bz2 |
Merge branch 'autossh' into 'master'
autossh support
this series of commits adds support for autossh, to automatically create a tunnel with port forwarding.
we use this to login to *really* remote servers reliably, behind multiple NATs and satellite connexions.
it rocks.
See merge request !18
Diffstat (limited to 'manifests')
-rw-r--r-- | manifests/autossh.pp | 40 |
1 files changed, 40 insertions, 0 deletions
diff --git a/manifests/autossh.pp b/manifests/autossh.pp new file mode 100644 index 0000000..5650584 --- /dev/null +++ b/manifests/autossh.pp @@ -0,0 +1,40 @@ +class sshd::autossh($host, + $port = undef, # this should be a remote->local hash + $remote_user = undef, + $user = 'root', + $pidfile = '/var/run/autossh.pid', +) { + if $port { + $port_ensure = $port + } + else { + # random port between 10000 and 20000 + $port_ensure = fqdn_rand(10000) + 10000 + } + if $remote_user { + $remote_user_ensure = $remote_user + } + else { + $remote_user_ensure = "host-$fqdn" + } + file { + '/etc/init.d/autossh': + mode => '0555', + source => 'puppet:///modules/sshd/autossh.init.d'; + '/etc/default/autossh': + mode => '0444', + content => "USER=$user\nPIDFILE=$pidfile\nDAEMON_ARGS='-M0 -f -o ServerAliveInterval=15 -o ServerAliveCountMax=4 -q -N -R $port_ensure:localhost:22 $remote_user_ensure@$host'\n"; + } + package { 'autossh': + ensure => present, + } + service { 'autossh': + ensure => running, + enable => true, + subscribe => [ + File['/etc/init.d/autossh'], + File['/etc/default/autossh'], + Package['autossh'], + ], + } +} |